VYPR

CVEs

38,095 total · page 315 of 762

  • CVE-2024-35049CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.

  • CVE-2024-34945CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at ip/goform/WizardHandle.

  • CVE-2024-34943CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.

  • CVE-2024-34706CriMay 14, 2024
    risk 0.57cvss 9.8epss 0.01

    Valtimo is an open source business process and case management platform. When opening a form in Valtimo, the access token (JWT) of the user is exposed to `api.form.io` via the the `x-jwt-token` header. An attacker can retrieve personal information from this token, or use it to…

  • CVE-2024-34555CriMay 14, 2024
    risk 0.65cvss 10.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in URBAN BASE Z-Downloads.This issue affects Z-Downloads: from n/a through 1.11.3.

  • CVE-2024-34440CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.2.63.

  • CVE-2024-34416CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Pk Favicon Manager.This issue affects Pk Favicon Manager: from n/a through 2.1.

  • CVE-2024-34411CriMay 14, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Thomas Scholl canvasio3D Light.This issue affects canvasio3D Light: from n/a through 2.5.0.

  • CVE-2024-34365CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative…

  • CVE-2024-34359CriMay 14, 2024
    risk 0.57cvss 9.6epss 0.26

    llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and…

  • CVE-2024-34340CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls…

  • CVE-2024-34226CriMay 14, 2024
    risk 0.61cvss 9.4epss 0.01

    SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.

  • CVE-2024-34213CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.

  • CVE-2024-34209CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function.

  • CVE-2024-34204CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter.

  • CVE-2024-34070CriMay 14, 2024
    risk 0.55cvss 9.6epss 0.01

    Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the…

  • CVE-2024-33874CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.

  • CVE-2024-32964CriMay 14, 2024
    risk 0.56cvss 9.0epss 0.53

    Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious…

  • CVE-2024-32735CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.07

    An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.

  • CVE-2024-32700CriMay 14, 2024
    risk 0.65cvss 10.0epss 0.03

    Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue affects Kognetiks Chatbot for WordPress: from n/a through 2.0.0.

  • CVE-2024-32622CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_extent_simple in H5S.c).

  • CVE-2024-32621CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.

  • CVE-2024-32615CriMay 14, 2024
    risk 0.57cvss 9.8epss 0.01

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an initialized pointer.

  • CVE-2024-32611CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.

  • CVE-2024-31810CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2024-31377CriMay 14, 2024
    risk 0.65cvss 10.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.7.01.001.

  • CVE-2024-30802CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Vehicle Management System 7.31.0.3_20230412 allows an attacker to escalate privileges via the login.html component.

  • CVE-2024-2257CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to improper implementation of password policies. An attacker with physical access could exploit this by creating password that do not adhere to the defined security…

  • CVE-2024-29895CriMay 14, 2024
    risk 0.66cvss 10.0epss 0.98

    Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option of PHP is `On`. In `cmd_realtime.php`…

  • CVE-2024-29212CriMay 14, 2024
    risk 0.64cvss 9.9epss 0.02

    Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

  • CVE-2024-29164CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

  • CVE-2024-29159CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

  • CVE-2024-29157CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

  • CVE-2024-28285CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges.

  • CVE-2024-28075CriMay 14, 2024
    risk 0.65cvss 9.0epss 0.78

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing…

  • CVE-2024-27280CriMay 14, 2024
    risk 0.57cvss 9.8epss 0.02

    A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value.…

  • CVE-2024-26517CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the delete-task.php component.

  • CVE-2024-25641CriMay 14, 2024
    risk 0.10cvss 9.1epss 0.86

    Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP…

  • CVE-2024-0087CriMay 14, 2024
    risk 0.60cvss 9.0epss 0.20

    NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denial of service,…

  • CVE-2023-47709CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.

  • CVE-2022-32504CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by the device leads to a stack buffer overflow. An attacker would be able to exploit this to gain arbitrary code execution on a…

  • CVE-2024-34257CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.04

    TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.

  • CVE-2024-25533CriMay 8, 2024
    risk 0.61cvss 9.4epss 0.01

    Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx). This vulnerability can allow attackers to write files to the server or execute arbitrary commands via crafted SQL statements.

  • CVE-2024-25532CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/get_dict.aspx.

  • CVE-2024-31961CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in unit.php in Sonic Shopfloor.guide before 3.1.3 allows remote attackers to execute arbitrary SQL commands via the level2 parameter.

  • CVE-2024-25531CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/SearchCondiction.aspx.

  • CVE-2024-25530CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/get_find_condiction.aspx.

  • CVE-2024-25529CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_office_file_history_show.aspx.

  • CVE-2024-25527CriMay 8, 2024
    risk 0.61cvss 9.4epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_show.aspx.

  • CVE-2024-32980CriMay 8, 2024
    risk 0.52cvss 9.1epss 0.00

    Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some specifically configured Spin applications that use `self` requests without a specified URL authority can be induced to make requests to arbitrary hosts via…